Impact
The vulnerability arises from insufficient runtime checks that can cause an application to trigger unexpected system termination. This results in a denial-of-service condition, disrupting the entire operating system and any running applications. The weakness is identified as CWE-400, indicating a resource exhaustion or improper handling scenario that may lead to system instability. Based on the description, it is inferred that an attacker would need to deliver a malicious app to the device.
Affected Systems
Apple devices running iOS and iPadOS with firmware versions older than the fixed releases of iOS 18.5, iPadOS 18.5, iPadOS 17.7.7, macOS with versions older than Sequoia 15.5, Sonoma 14.7.6, and Ventura 13.7.6, tvOS with versions older than 18.5, or visionOS with versions older than 2.5 are affected.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% reflects a low probability of exploitation at present. The vulnerability is not catalogued in CISA KEV. It is inferred that likely exploitation requires the attacker to run a malicious or vulnerable app on the device, suggesting a local or user‑initiated attack vector.
OpenCVE Enrichment
EUVD